Security & Privacy
Our customers trust us with highly sensitive information: the compensation of their employees. We take this responsibility seriously and built our products from the ground up with security and privacy in mind, including enterprise-grade protections, regular audits, and strong privacy standards.

Pave meets leading security standards
ISO27001 Certified
Pave is ISO/IEC 27001:2022 certified, demonstrating our adherence to rigorous international standards for information security. This certification underscores our dedication to systematically managing sensitive information and ensuring data integrity.
SOC 2 Type 1 Compliance
Pave is SOC 2 Type 1 compliant. This attestation verifies we have effective controls in place for financial reporting, ensuring the accuracy and reliability of financial data processed through our platform.
SOC 2 Type 2 Compliance
Pave is SOC 2 Type 2 compliant. This attestation verifies our systems are designed to keep customer data secure, available, and confidential over time, reflecting the our commitment to ongoing operational excellence.
Take charge of your ecosystem with Pave
Pave enables best-in-class security for every client using the our platform. We offer Single-Sign-On (SSO) authentication, role-based access controls, and in-product data protection protocols to ensure you can confidently share sensitive compensation information based on the privileges you set for leaders, people managers, and employees.

Pave integrates privacy into every process
GDPR & CCPA
Pave adheres to the California Consumer Privacy Act (CCPA) and the European Union’s General Data Protection Regulation (GDPR), ensuring data is processed lawfully, transparently, and securely. We work closely with clients to meet their compliance requirements under these regulations.
Aggregated & De-Identified Data
Pave does NOT use personally identifiable information (PII) in our Market Data products. These products only use aggregated and de-identified data.
Enterprise-Grade Data Storage
Pave stores data in the United States, utilizing enterprise-grade cloud storage provided by Google Data Centers. We follow data storage best practices that comply with relevant regulations and industry standards.
Data Access
Pave enforces the principle of “Least Privilege,” ensuring employees only have access to the data necessary for their roles. This approach minimizes the risk of unauthorized data exposure and maintains strict confidentiality.
Data Transfers
Pave uses the most up to date Standard Contractual Clauses for transfers between customers and Pave, and between Pave and our subprocessors.
Going the extra mile to protect clients
Beyond the security and privacy protections listed above, Pave goes even further to protect clients. We have a dedicated security team, we conduct bi-annual penetration testing through third-party providers, we encrypt data at rest and in transit, and we run a paid bug bounty program.
